Ep. 74 - CTEM's Silent E: DORA, NIS2 and the End of Security by Attestation
Regulators stopped asking whether you have security controls. Now they want proof the controls actually work. Host Tova Dvorin sits down with Adrian Culley to argue that CTEM has a silent E—for evidence—and that evidence is now the currency of cyber regulation worldwide. Inside: DORA's Article 26 threat-led penetration testing, NIS2's "assess the effectiveness" clause and personal board liability, the SEC's 8-K materiality clock, NYDFS Part 500's personally signed CISO certification, and the EU AI Act's August logging deadline. Subscribe to The Cyber Resilience Brief for more.